Confidential computing's core trust mechanism is broken. The fix may not exist
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
New research from TU Dresden formally verifies that attested TLS, the protocol underpinning confidential computing's trust guarantees, is fundamentally broken. Using ProVerif, researchers found that all seven examined intra-handshake attestation binding mechanisms fail to prevent relay attacks, where a client verifies a genuine TEE but ends up sending encrypted data to a malicious machine. The flaw affects production systems including Meta's WhatsApp Private Processing, Edgeless Systems' Contrast, and Cocos AI (CVE-2026-33697, CVSS 7.5). The best available fix achieves only level-two binding, proving identity at handshake start but not during data transmission. Level-three binding, which would protect actual application traffic, may be architecturally impossible within intra-handshake attestation. Germany's BSI independently confirmed that confidential computing falls short of digital sovereignty claims. The researchers recommend abandoning intra-handshake attestation in favor of post-handshake attestation, and the IETF's SEAT working group has incorporated formal verification requirements into its charter. Vendor-dominated CCC working groups delayed publishing the vulnerability artifacts for over ten days despite repeated requests.